Canadian Man Pleads Guilty in Snowflake Extortions

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Connor Riley Moucka, 26, of Kitchener, Ontario pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy for the 2024 Snowflake data thefts, and faces a mandatory minimum of 2 years plus up to 30 years when sentenced October 27.
- Moucka and co-conspirators used stolen login credentials for Snowflake accounts without multi-factor authentication to steal billions of customer records — including 100M+ AT&T call/text history records, DEA registration numbers, SSNs, and passport numbers — earning $2.5M+ in ransom payments.
- Victims included TicketMaster, Lending Tree, Advance Auto Parts, and Neiman Marcus; in one instance Moucka re-extorted a government officer by threatening to expose data belonging to the officer's immediate family, per the Justice Department.
- Co-conspirator Cameron "Kiberphant0m" Wagenius, a U.S. Army soldier, pleaded guilty in July 2025 and after Moucka's arrest posted on hacker forums what he claimed were AT&T call logs for then-President-elect Trump and VP Kamala Harris plus alleged NSA schematics; he faces sentencing September 3, 2026.
- Third alleged co-conspirator John Erin Binns — indicted for the 2021 T-Mobile breach exposing 76M customers — recently obtained Turkish citizenship, which under Turkish law may shield him from U.S. extradition, according to sources close to the investigation.
- Snowflake responded to the thefts by enforcing multi-factor authentication across customer accounts and increasing password complexity requirements.
Why it matters: Moucka's plea closes one chapter of a sprawling case that exposed how a single missing MFA toggle across Snowflake customers enabled the theft of billions of records and $2.5M+ in ransom — and the Binns extradition roadblock means at least one alleged co-conspirator likely won't face U.S. court.
Ask SkimNews



